US10116630B2

Systems and methods for decrypting network traffic in a virtualized environment

Summary by NHIP

Virtual Machine Traffic Decryption

The system executes an introspection engine outside a virtual machine to identify memory pages changing between handshake and session completion events. A decryption engine then uses content from these identified pages to decrypt intercepted encrypted payloads.

Claim Score by NHIP

Read claim 22, the broadest

Abstract

Described systems and methods enable a decryption of encrypted communication between a client system and a remote party, for applications such as detection and analysis of malicious software, intrusion detection, and surveillance, among others. The client system executes a virtual machine and an introspection engine outside the virtual machine. The introspection engine is configured to identify memory pages whose contents have changed between a first session event (e.g., a ServerHello message) and a second session event (e.g., a ClientFinished message). The respective memory pages are likely to contain encryption key material for the respective communication session. A decryption engine may then attempt to decrypt an encrypted payload of the respective communication session using information derived from the content of the identified memory pages.

US10116630B2, drawing sheet 1
Sheet 1 of 9

Term

10.8 yearsleft in the term

Expires 12 July 2037, including 106 days of term adjustment.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

22 claims: 4 independent, 18 dependent

  1. 1
    A client system comprising a hardware processor and a memory, the hardware processor configured to execute a virtual machine, an introspection engine, and a network filter, the introspection engine and the network filter executing outside of the virtual machine, wherein:the virtual machine is configured to carry out a communication session with a remote party, the communication session comprising a handshake message followed by an encrypted payload, wherein the handshake message contains an encryption parameter used by the client system to derive an encryption key, and wherein the encrypted payload is encrypted with the encryption key;the network filter controls a network adapter of the client system and is configured to intercept the handshake message and in response, transmit a notification to the introspection engine;and the introspection engine is configured to: infer an occurrence of a first session event of the communication session according to the notification, identify within the memory a target memory page according to whether a content of the target memory page has changed between the occurrence of the first session event and an occurrence of a second session event of the communication session, and in response, transmit the content of the target memory page to a decryption engine configured to decrypt the encrypted payload according to the content.
  2. 10
    A server computer system comprising a hardware processor configured to execute a decryption engine configured to carry out decryption procedures for a plurality of client systems, a decryption procedure comprising:receiving an encrypted payload of a communication session carried out between a virtual machine executing on the client system and a remote party;and in response, decrypting the encrypted payload according to the content of the target memory page, wherein the communication session comprises a handshake message followed by the encrypted payload, wherein the handshake message contains an encryption parameter used by the client system to derive an encryption key, wherein the encrypted payload is encrypted with the encryption key, and wherein the client system is configured to execute an introspection engine and a network filter, the introspection engine and the network filter executing outside of the virtual machine, wherein: the network filter controls a network adapter of the client system and is configured to intercept the handshake message and in response, transmit a notification to the introspection engine, and the introspection engine is configured to: infer an occurrence of a first session event of the communication session according to the notification, and identify the target memory page within a memory of the client system according to whether the content of the target memory page has changed between the occurrence of the first session event and an occurrence of a second session event of the communication session.
  3. 21
    A non-transitory computer-readable medium storing instructions which, when executed by a hardware processor of a client system further comprising a memory, cause the hardware processor to form an introspection engine and a network filter, the introspection engine and network filter executing outside a virtual machine executing on the client system, wherein:the virtual machine is configured to carry out a communication session with a remote party, the communication session comprising a handshake message followed by an encrypted payload, wherein the handshake message contains an encryption parameter used by the client system to derive an encryption key, and wherein the encrypted payload is encrypted with the encryption key;the network filter controls a network adapter of the client system and is configured to intercept the handshake message and in response, to transmit a notification to the introspection engine;and the introspection engine is configured to: infer an occurrence of a first session event of the communication session according to the notification, identify within the memory a target memory page according to whether a content of the target memory page has changed between the occurrence of the first session event and an occurrence of a second session event of the communication session, and in response, transmit the content of the target memory page to a decryption engine configured to decrypt the encrypted payload according to the content.
  4. 22
    Broadest claimClaim Score 47, average(NHIP)A method of decrypting encrypted communications between a client system and a remote party, wherein the client system is configured to execute a virtual machine, wherein:the virtual machine is configured to carry out a communication session with the remote party, the communication session comprising a handshake message followed by an encrypted payload, wherein the handshake message contains an encryption parameter used by the client system to derive an encryption key, and wherein the encrypted payload is encrypted with the encryption key, the method comprising: employing at least one hardware processor of the client system to intercept the handshake message;employing the at least one hardware processor to infer an occurrence of a first session event of the communication session according to the interception;employing the at least one hardware processor to identify within a memory of the client system a target memory page according to whether a content of the target memory page has changed between the occurrence of the first session event and an occurrence of a second session event of the communication session;employing the at least one hardware processor to harvest the encrypted payload;and decrypting the encrypted payload according to the content of the target memory page.